Plaintext checkable encryption with designated checker

  • This paper introduces a new public-key primitive called designated plaintext checkable encryption (DPCE) in which given a ciphertext, a delegated checker can determine whether the ciphertext decrypts under the same public key to a plaintext chosen by himself. Motivated by various applications, two types of DPCE (of Type-I and II) are defined, depending upon whether the user delegates the plaintext checking right at his will to a delegated checker (Type-I) or the user is required to provide this plaintext checking right to a designated checker (Type-II). We propose several generic random-oracle and standard model constructions for DPCE of both the types based on arbitrary probabilistic or deterministic encryption schemes.
